From: Johannes Schindelin Date: Thu, 24 Sep 2026 18:59:24 GMT Subject: Re: [PATCH] ci: work around Debian 12's HTTP/2 authentication failures Message-ID: In-Reply-To: <20260923192514.GA43344@coredump.intra.peff.net> Hi Jeff, On Wed, 23 Sep 2026, Jeff King wrote: > On Wed, Sep 23, 2026 at 10:17:05AM -0700, Junio C Hamano wrote: > > > Jeff King writes: > > > > > +# Curl 7.88.1 can fail to retry authentication after an early HTTP/2 > > > +# response. This was fixed in curl 8.3.0; see > > > +# https://github.com/curl/curl/pull/11756. The first affected version is > > > +# unknown, so conservatively assume that versions from 7.88.1 up to (but > > > +# not including) 8.3.0 are broken. > > > > Just nitpicking the wording, but if the first affected version is > > truly unknown, assuming that versions from 7.88.1 up is *not* a > > conservative thing to do at all, is it? > > > > If 7.88.1 is from an irrelevantly ancient past, I would say that we > > should just skip anything older than 8.3.0, but 7.88.1 is from early > > 2023 and we cannot do such a simplification. > > It depends on what bad outcome we are being conservative against. If the > bad outcome is skipping the test on a version for which we could > reliably use it, then it is conservative to only select known-bad > versions. If the bad outcome is somebody running the test and seeing a > flaky fail, then yes, the more conservative thing would be extending to > skip older unknown versions (potentially up to "forever"). > > I think you could argue either way (and I am OK with either, or even > just matching 7.88.1). I had GPT-6 dig deeper into the issue, since you're right: This should not be a CI/Debian-only gate, at the same time I didn't know what was the first version with the bug, so I suspected the version range to be subtly inaccurate. Turns out that the bug appeared first in cURL v7.88.0. So I adjusted your version range in preparation for the next patch iteration. Thank you! Johannes